CVE Vulnerabilities

CVE-2001-1377

Published: Mar 04, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Affected Software

NameVendorStart VersionEnd Version
FreeradiusFreeradius0.2 (including)0.2 (including)
FreeradiusFreeradius0.3 (including)0.3 (including)
RadiusGnu0.92.1 (including)0.92.1 (including)
RadiusGnu0.93 (including)0.93 (including)
RadiusGnu0.94 (including)0.94 (including)
RadiusGnu0.95 (including)0.95 (including)
IcradiusIcradius0.14 (including)0.14 (including)
IcradiusIcradius0.15 (including)0.15 (including)
IcradiusIcradius0.16 (including)0.16 (including)
IcradiusIcradius0.17 (including)0.17 (including)
IcradiusIcradius0.17b (including)0.17b (including)
IcradiusIcradius0.18 (including)0.18 (including)
IcradiusIcradius0.18.1 (including)0.18.1 (including)
RadiusLivingston2.0 (including)2.0 (including)
RadiusLivingston2.0.1 (including)2.0.1 (including)
RadiusLivingston2.1 (including)2.1 (including)
RadiusLucent2.0 (including)2.0 (including)
RadiusLucent2.0.1 (including)2.0.1 (including)
RadiusLucent2.1 (including)2.1 (including)
RadiusMiquel_van_smoorenburg_cistron1.6.1 (including)1.6.1 (including)
RadiusMiquel_van_smoorenburg_cistron1.6.2 (including)1.6.2 (including)
RadiusMiquel_van_smoorenburg_cistron1.6.3 (including)1.6.3 (including)
RadiusMiquel_van_smoorenburg_cistron1.6.4 (including)1.6.4 (including)
RadiusMiquel_van_smoorenburg_cistron1.6.5 (including)1.6.5 (including)
RadiusMiquel_van_smoorenburg_cistron1.6_.0 (including)1.6_.0 (including)
OpenradiusOpenradius0.8 (including)0.8 (including)
OpenradiusOpenradius0.9 (including)0.9 (including)
OpenradiusOpenradius0.9.1 (including)0.9.1 (including)
OpenradiusOpenradius0.9.2 (including)0.9.2 (including)
OpenradiusOpenradius0.9.3 (including)0.9.3 (including)
RadiusclientRadiusclient0.3.1 (including)0.3.1 (including)
XtradiusXtradius1.1_pre1 (including)1.1_pre1 (including)
XtradiusXtradius1.1_pre2 (including)1.1_pre2 (including)
Yard_radiusYard_radius1.0.17 (including)1.0.17 (including)
Yard_radiusYard_radius1.0.18 (including)1.0.18 (including)
Yard_radiusYard_radius1.0.19 (including)1.0.19 (including)
Yard_radiusYard_radius1.0_pre13 (including)1.0_pre13 (including)
Yard_radiusYard_radius1.0_pre14 (including)1.0_pre14 (including)
Yard_radiusYard_radius1.0_pre15 (including)1.0_pre15 (including)
Yard_radiusYard_radius_project1.0.16 (including)1.0.16 (including)
Red Hat Powertools 7.0RedHat*
Red Hat Powertools 7.1RedHat*

References